Do you know, off hand, whether or not WordPress would run properly (and
securely) if Apache was configured to execute all PHP code using FPM
instead of mod_php? (Or should I ask that on the WordPress forum?)

Any common application should work unmodified.

What is your take on Facebook's Hack with HHVM, as a putative
replacement for PHP FPM?